Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Librechat
Librechat librechat |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:librechat:librechat:0.8.2:rc2:*:*:*:*:*:* cpe:2.3:a:librechat:librechat:0.8.2:rc3:*:*:*:*:*:* |
|
| Vendors & Products |
Librechat
Librechat librechat |
Mon, 30 Mar 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Danny-avila
Danny-avila libre Chat |
|
| Vendors & Products |
Danny-avila
Danny-avila libre Chat |
Fri, 27 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Mar 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc2 through 0.8.2-rc3, the SSE streaming endpoint `/api/agents/chat/stream/:streamId` does not verify that the requesting user owns the stream. Any authenticated user who obtains or guesses a valid stream ID can subscribe and read another user's real-time chat content, including messages, AI responses, and tool invocations. Version 0.8.2 patches the issue. | |
| Title | LibreChat's IDOR in SSE Stream Subscription Allows Reading Other Users' Chats | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-27T19:55:24.141Z
Reserved: 2026-03-10T15:10:10.657Z
Link: CVE-2026-31950
Updated: 2026-03-27T19:55:21.101Z
Status : Analyzed
Published: 2026-03-27T20:16:30.217
Modified: 2026-03-30T20:32:16.933
Link: CVE-2026-31950
No data.
OpenCVE Enrichment
Updated: 2026-03-31T20:00:50Z